Showing posts with label users. Show all posts
Showing posts with label users. Show all posts

Monday, 30 September 2013

Google's redesigned tab page annoys some Chrome users

Google last week started rolling out a redesigned new tab page for Chrome, making good on a promise from last month when it offered the revamp to users running rougher-edged versions of its browser.

Most users gave the new look a failing grade. "Fail, fail, fail," said Philip Wright, one of those who commented on the announcement.

Google characterized the addition as a way to speed up search.

"We're rolling out a feature that can make searching faster and simpler with a streamlined New Tab page," said the Chrome team on its Google+ page. "If you use Google as your default search engine, the next time you open a new tab in Chrome the search bar will be front and center ... [and] you'll also be able to check out current Google Doodles."

chrome

The new tab page appears when users press Ctrl-T (Windows) or Command-T (OS X) in Chrome. All browsers offer a similar new tab page that, at a minimum, shows thumbnails of the user's most visited websites. The feature, which debuted on Opera, has been copied by all its rivals, including Chrome, Microsoft's Internet Explorer, Mozilla's Firefox, and Apple's Safari.

Firefox was the last to acquire a graphical new tab page when in June 2012 Mozilla released Firefox 13.

Chrome's new tab page redesign sports a prominent Google search field as the only real difference between it and its predecessor. The page still displays eight thumbnails of the user's most-called-on sites.

But Chrome users just didn't get it.

"If you're on Chrome, why wouldn't you just use the omnibar?" asked commenter Neil Slater, using an alternate name for "omnibox," Google's label for the combined search-address bar at the top of the browser window. "To use this new search box it takes an extra mouse click to put the cursor into the box. The cursor's already by default in the omnibar on opening a new tab."

Many commenters dismissed the change as useless, with some asking how to revert to the previous design. Others were dismayed that Google moved the Chrome Apps button—which calls up a display of the browser's installed Web apps—to the bookmark bar.

Google has faced resistance from Chrome users before when it has proposed redesigns of the new tab page. In April, Google backtracked from a refreshed new tab page that had reduced the number of thumbnails from eight to four, inserted a large Google search box, shifted the Web apps view to a button, and dumped other features, including the ability to view recently closed tabs, from the page.

Most of those changes, however, were implemented in the final new tab page that began reaching users Tuesday. The most visible that did not was the four-thumbnail view.

Users who want to restore the previous design should type "chrome://flags" in the omnibox—minus the quotation marks—locate the "Enable Instant Extended API" setting in the long list, and change it from "Enable" to "Disable."

\

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news.
More by Gregg Keizer, Computerworld


View the original article here

Friday, 27 September 2013

Another borked Microsoft update tells Office Starter Edition users to buy the suite

Microsoft yesterday acknowledged yet another problem with its Sept. 10 updates, confirming that one of those fixes broke Office 2010 Starter Edition by changing the file associations of already-created documents.

"After installing this update, some users have reported they are unable to open files by double-clicking them, that the file type icons have changed, and that they must go to the application to open files," Microsoft's Office team said in a company blog post Wednesday.

Some customers, said Microsoft, were even told that they needed to buy a copy of the full-scale Office, which starts at $140 for Office Home & Student 2013.

Naturally, that caused some customers to wig out, as their suite—Office 2010 Starter Edition—had come free with their PCs.

Gmail hit by message delivery delays, close to 50 percent of users affected

A bug bit Gmail Monday and almost half of the webmail service’s users are experiencing email delivery delays and problems downloading attachments.

Google first acknowledged the problem shortly before 7:30 a.m. PDT and has been wrestling with it ever since, according to information on the Google Apps Status page.

In an update posted at around 2 p.m. PDT, the company disclosed that “less than 50 percent” of users had been impacted, which can safely be assumed to mean that at least 49 percent of users got hit.

Gmail has more than 425 million active users.

The Google Docs word-processing application and Presentation slide-creation application have also been experiencing a disruption during the same timeframe, but the company hasn’t disclosed the nature of that problem and the scope of users impacted.

In the latest update, posted at 1 p.m. PDT, Google said Gmail service had been restored "for most affected users" and that it expects to have the problem solved for everyone affected by 4 p.m. PDT. That's three hours longer than the previous resolution estimate.

"We expect a small and declining number of messages to still be affected for the next 3 hours as the remaining delivery backlog is cleared. We are working on several options to accelerate the process and will provide more information when we have an updated time estimate," the note reads.

The Google Docs word processing application and Presentation slide creation application also had a service disruption that started about 7:30 a.m. PDT and lasted until 1 p.m. PDT. The company hasn't disclosed the nature of the problem that affected those cloud applications nor the scope of affected users.

The duration of the outage and the number of people affected make this incident a very significant one for Google, which is involved in a brutal fight with Microsoft in the market for enterprise cloud email and collaboration apps.

Monday's outage is affecting not only individuals who use Gmail for free but also businesses, schools, and government agencies that use it as part of the fee-based Google Apps suite, as evidenced by multiple Twitter posts and discussion forum threads.

Google Apps competes directly with Microsoft's Office 365, and the two rivals are constantly trumpeting customer wins and sniping at each other's product suites.

A Google spokeswoman declined to comment on the matter beyond what's been posted on the Apps Status site.

 Updated 9/23/2013 at 2:20 p.m. PDT 

Juan Carlos Perez covers e-commerce, Google, web-application development, and cloud applications for the IDG News Service.
More by Juan Carlos Perez


View the original article here

Google's Gmail scanning unclear to users, judge finds

A U.S. federal judge allowed a class-action suit against Google to proceed, saying the company's terms of service are unclear when describing how it scans Gmail content in order to deliver advertisements.

Google had filed a motion to dismiss the suit, which alleges that the company intercepted and read email while in transit in order to deliver advertisements and create user profiles and models since 2008. The plaintiffs alleged the company violated federal and state wiretapping laws.

The suit, which is being heard in U.S. District Court for the Northern District of California, further contends non-Gmail users who sent email to Gmail users were also subject to illegal interception.

In her ruling Thursday, U.S. District Judge Lucy H. Koh wrote that Google's terms of service and privacy policies do not explicitly say that the company intercepts users' email to create user profiles or deliver targeted advertising.

Although Google revised its terms of service and privacy policy in 2012, Koh wrote "that a reasonable Gmail user who read the Privacy Policies would not have necessarily understood that her emails were being intercepted to create user profiles or to provide targeted advertisements."

Google said in a statement it was disappointed with the decision and is considering its options. "Automated scanning lets us provide Gmail users with security and spam protection, as well as great features like Priority Inbox."

Google, which had filed a motion to dismiss, maintains that the automated scanning is fully disclosed to Gmail users and that features such as search and filtering would not be possible without it.

Past court rulings have also held that all email users imply consent to automated processing since email couldn't be sent otherwise, Google argued in the motion.

Koh also rejected Google's contention that non-Gmail users gave their implied consent to scanning of their communications.

"Google has cited no case that stands for the proposition that users who send emails impliedly consent to interceptions and use of their communications by third parties other than the intended recipient of the email," Koh wrote.

Consumer Watchdog, a nonprofit consumer advocate group based in Washington, D.C., called Koh's ruling a "tremendous victory for online privacy."

"The court rightly rejected Google's tortured logic that you have to accept intrusions of privacy if you want to send email," said John M. Simpson, Consumer Watchdog's privacy project director, in a news release. "Companies like Google can't simply do whatever they want with our data and emails."

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here

Tuesday, 24 September 2013

Startup connects brands with influential Instagram users

Online photo sharing services like Instagram and Pinterest can be remarkably effective branding tools. While neither platform officially employs ads, the social media teams of marketing-savvy companies often build relationships with well-followed users, either paying them to post photos of their products, or giving them stuff in trade for doing it.

Mercedes, for example, recently loaned a CLA to five top Instagrammers who took photos of the 4-door coupe during a five-day road trip. At the end, the one with the most “likes” got to keep the car.

But identifying and cultivating relationships with social media darlings individually puts an additional burden on most companies’ already stretched marketing resources. Brandnew IO wants to lend a hand. The Berlin-based startup, founded earlier this year, connects brands with influential users on Instagram and Pinterest and pays those users to share the brands’ images.

Brandnew IOBrandnew IO works with influential Instagram users to promote brand content.

It’s not just pimping out popular feeds, though. These “publishers”—people with an average of 300,000 followers—obviously have a vested interest in not annoying and losing fans. As such, they’re under no obligation to promote content that doesn’t mesh with the ethos of their feeds.

So far Brandnew IO has about 180 publishers, people who tend to be photographers, aspiring celebrities, and bloggers who post images focused on subject areas such as fashion, beauty, and cars. Their collective reach, Brandnew IO founder and CEO Francis Trapp told me via Skype, is a massive 55 million followers.

Similar to a CPM model, Brandnew IO charges client companies per 1,000 users, with niche campaigns—ones that reach people who only upload photos of car rims, for example—going for a premium. Targeting a broader market, such as folks who like to upload photos of fashion or beauty, costs less.

Brandnew IO also provides advertisers with analytics that help them gauge the effectiveness of their campaigns.

While Trapp says Brandnew IO is required to label the images publishers post as advertisements, he believes sponsored content posted by users is more effective than banner ads.

“When you look at the photos we publish throughout our campaigns, they appear in the Instagram user photo feed and [are] completely merged with the surrounding photos so it’s 100 percent native,” Trapp says. “As a result, the KPIs and conversion rates and engagement rates are a lot higher, for example, than Facebook ads and Facebook sponsored posts in the news feed.”

Instagram and Pinterest themselves are both keen on monetizing their platforms with ads. Last week at a fashion event in London, Instagram co-founder and CEO Kevin Systrom said it has plans to launch ads within the next year. A few days later Pinterest CEO Ben Silberman said in an email to users the photo-pinning company will be playing around with promoting a handful of pins in search results and category feeds.

Silberman promised that promoted pins will not involve “flashy banners or pop-up ads.” Systrom’s remarks hinted that its approach might also be one in which users aren’t pushed overt ads, but rather shown products within the context of their feed, prompting them to like and comment on the post.

Such a tack would make sense considering the way companies have tended to connect with fans on these platforms so far. Followers follow because they have an emotional connection with a brand and the absence of jarring ads puts the onus on companies to share engaging content so as to woo users and win more hearts, not to mention pins and comments.

As for Brandnew IO, Trapp says he plans to grow his six-person team to 10 or 15 by the end of the year. The company just closed a six-digit round of seed funding, which it will use to acquire more advertisers and publishers as well as connect with additional photo sharing communities.

Christina is a contributor to media outlets such as Forbes.com, Inc.com, PCWorld.com, Auto Trader and The Minneapolis Star Tribune. She writes about a myriad of topics including technology, the automotive industry and health and fitness. Her talents outside of writing include photography, getting people to talk (although that certainly helps with writing) and gardening.
More by Christina DesMarais


View the original article here

Thursday, 5 September 2013

Most Internet users take steps to avoid surveillance

IDG News Service - A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center's Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey's findings are based on telephone interviews among a sample of 1,002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers' use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user's real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. "Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid," Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Most Internet users take steps to avoid surveillance

IDG News Service - A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center's Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey's findings are based on telephone interviews among a sample of 1,002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers' use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user's real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. "Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid," Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Survey: Almost 90 percent of Internet users have taken steps to avoid surveillance

A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center’s Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey’s findings are based on telephone interviews among a sample of 1002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers’ use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user’s real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. “Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid,” Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Discovering that many Internet users have tried to conceal their identity or their communications from others was the biggest surprise to the research team, they said in a news release. Not only hackers, but almost everyone has taken some action to avoid surveillance and despite their knowing that anonymity is virtually impossible, most Internet users think they should be able to avoid surveillance online, they said.

Most U.S. citizens would like to be anonymous and untracked online, at least every once in a while, but many think it is not possible to be completely anonymous online, Pew said. “This reinforces the notion that privacy is not an all-or-nothing proposition for internet users. People choose different strategies for different activities, for different content, to mask themselves from different people, at different times in their lives,” the researchers wrote.

One of the most revealing contradictions in the results of the survey is that those who have taken steps to try to avoid observation by others and those who have taken more general steps to be anonymous are more likely than others to have personal information posted online, the researchers said.

Internet users surveyed said they have a photo of themselves online (66 percent), while about half of those polled said their birth date was available online. A minority said that their email address, home address, mobile number or political affiliation was available.

A majority of Web users polled, 66 percent, said they think current privacy laws are not good enough to provide reasonable protections for people’s privacy on their online activities.

“Interestingly, there are not noteworthy differences in answers to this question associated with political or partisan points of view. Tea Party supporters, conservative Republicans, self-described moderates, and liberal Democrats are not statistically significantly different in their answers,” the researchers wrote.

Loek Essers focuses on online privacy, intellectual property, open-source and online payment issues.
More by Loek Essers, IDG News Service


View the original article here

Monday, 2 September 2013

Trojan entices Craigslist users with fake software freebie

Craigslist has made some strides over the years in protecting its users from Internet predators, but for some hackers those strides are just another challenge to be surmounted.

That's the case with a Trojan aimed at the online classified advertising service and revealed last week by Solera, a Blue Coat company.

The malware is ending up on the computers of unsuspecting users who click an infected link they encounter on the Internet, expecting to receive an update to a fictitious program called Adobe Photo Loader. (See also "Lose the Trojan.")

After infecting a machine, the malware transforms the computer into a zombie for a botnet making spam postings to Craigslist for a program called Stealth Nanny. The Android app is designed to be planted on a person's phone so all their activity on the handset can be monitored by a snooper.

"We don't see a lot of spam on the service, but when we do, it's interesting because it's stuff that has figured out a way to get around these roadblocks set up by the guys running the site," Solera's Director of Threat Research, Andrew Brandt, said in an interview.

When this Trojan contacts Craigslist, it's armed with information sent to it by the command and control (C&C) server running the botnet that enables it to set up an account on the service and post the advertising copy for Stealth Nanny.

Before a listing can go live on Craigslist, its sponsor must verify it by email. The email confirmations for the ads posted by the Trojan are forwarded to it by its C&C server. "The bot then parses the Craigslist activation links, return them as a click through a browser without the browser user's knowledge and make the post go live," Brandt explained.

"It's a complicated mechanism that they've rigged up," he said. "It's amazing that it works, but it is quite functional."

The master of the zombie network has taken measures to keep the scheme off the radar of Craigslist spam fighters, Brandt added. "He'll do one post a day per infected machine."

The limited nature of the malware is also probably keeping its profile low. "It's a very bespoke malware for this specific purpose of just posting to Craigslist," Brandt said. "And the only thing we've seen it posting to Craigslist is this advertisement for this software that monitors cell phones."

Brandt added that he suspects that the maker of the software is also connected to the malware. All but one domain connected to the scheme was "private," he said. That one identifiable domain, however, contained a name, city and state that matched the same information in Stealth Nanny.

"It's clear to me that they're connected and entirely possible that the same person is responsible for Stealth Nanny and the malware," Brandt said.

Although the malware has a highly specific purpose now, once a machine is infected, the bad app could be repurposed for greater malignancy in the future. "Anytime a computer is infected with malware, the box is owned by someone else and they can use it to do all kinds of different things," Brandt said.

Mike Gross, director of professional services and risk management at 41st Parameter, said that credential theft is always a possibility with this kind of malware. "The biggest risk is always key loggers that essentially give the attackers access to any account where the legitimate user enters a username-password combination online," he told CSOonline.

In addition, since the botnet is controlled elsewhere on the Web, it likely has an auto-update function for downloading and modifying what's on an infected machine. "An auto-update feature would make the possibilities of danger endless for the infected device," said Tommy Chin, a technical support engineer with Core Security.

Craigslist did not respond to a request for comment for this report.

"Craigslist is a relatively open environment, with no strong validation of posts," Gross said. "It relies on users to post legitimate classifieds. Its primary form of policing spam is by user feedback, which is very reactive."

The online classifieds service is also largely free, which may also be contributing to its being a target of Internet lowlifes. "It's much easier to target a free service than it is a paid service," Chin said. "Free services require much less verification on the user's part."

"The site is also still in its infancy in regards to anti-spam and security practices," he said.

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Friday, 30 August 2013

vBulletin users warned of potential exploit

IDG News Service - The developers of the popular vBulletin commercial Internet forum software are investigating a potential exploit and advised users to delete the "install" directory from their deployments as a precaution.

"A potential exploit vector has been found in the vBulletin 4.1+ and 5+ installation directories," Wayne Luke, technical support lead at vBulletin Solutions, the company that develops the software, announced this week on the vBulletin community forum. "Our developers are investigating this issue at this time. If deemed necessary we will release the necessary patches."

Luke advised users to delete the 'install' directory from their vBulletin installations in order to mitigate the issue that hasn't yet been disclosed. The directory that should be deleted is "/install" for vBulletin 4.1.x versions and "/core/install" for the 5.x versions.

This directory normally contains the scripts and files used during the original installation process and subsequent upgrades.

In the "Cleaning up after Install" section of the vBulletin manual users are advised to delete all files and subdirectories from the "install" directory as a security precaution. However, they are not advised to delete the directory itself.

It's not clear what the exploit currently being investigated would allow potential attackers to do, but the fact that it prompted an advance warning from the developers suggests that it might have serious implications.

Luke declined to disclose information about the nature of the exploit.

"I am sorry but in the interest of security for our customers, we can not discuss this issue at this time," he said Thursday via email.

"Going back to our logs, we dont see any specific scans for /core/install, but we see constant discovery requests for /install," said Daniel Cid, chief security officer at Sucuri, a company that provides website security monitoring and malware clean-up services, in a blog post. "We dont yet know if that is related to vBulletin or other CMSs [content management systems]."

Attackers are constantly trying to exploit vulnerabilities in popular content management systems in order to break into websites, and while vBulletin does not power as many websites as WordPress, Joomla or some other general-purpose CMS software, it is one of the most popular applications for setting up Internet discussion forums.

According to vBulletin Solutions, over 100,000 community websites are running on vBulletin, including some operated by Zynga, Electronic Arts, Sony Pictures, NASA, Valve Corporation and other well known companies.

In July, hackers broke into UbuntuForums.org, a community website for the Ubuntu Linux distribution with over 1.8 million registered accounts, and managed to access information about users, including email addresses and password hashes. The site was using vBulletin.

"In summary, the root cause was a combination of a compromised individual account and the configuration settings in vBulletin, the Forums application software," Canonical, the company that operates the site, said in a blog post following the incident.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

vBulletin Internet forum software users warned of potential exploit

The developers of the popular vBulletin commercial Internet forum software are investigating a potential exploit and advised users to delete the “install” directory from their deployments as a precaution.

“A potential exploit vector has been found in the vBulletin 4.1+ and 5+ installation directories,” Wayne Luke, technical support lead at vBulletin Solutions, the company that develops the software, announced this week on the vBulletin community forum. “Our developers are investigating this issue at this time. If deemed necessary we will release the necessary patches.”

Luke advised users to delete the ‘install’ directory from their vBulletin installations in order to mitigate the issue that hasn’t yet been disclosed. The directory that should be deleted is “/install” for vBulletin 4.1.x versions and “/core/install” for the 5.x versions.

This directory normally contains the scripts and files used during the original installation process and subsequent upgrades.

In the “Cleaning up after Install” section of the vBulletin manual users are advised to delete all files and subdirectories from the “install” directory as a security precaution. However, they are not advised to delete the directory itself.

It’s not clear what the exploit currently being investigated would allow potential attackers to do, but the fact that it prompted an advance warning from the developers suggests that it might have serious implications.

Luke declined to disclose information about the nature of the exploit.

“I am sorry but in the interest of security for our customers, we can not discuss this issue at this time,” he said Thursday via email.

“Going back to our logs, we dont see any specific scans for /core/install, but we see constant discovery requests for /install,” said Daniel Cid, chief security officer at Sucuri, a company that provides website security monitoring and malware clean-up services, in a blog post. “We dont yet know if that is related to vBulletin or other CMSs [content management systems].”

Attackers are constantly trying to exploit vulnerabilities in popular content management systems in order to break into websites, and while vBulletin does not power as many websites as WordPress, Joomla or some other general-purpose CMS software, it is one of the most popular applications for setting up Internet discussion forums.

According to vBulletin Solutions, over 100,000 community websites are running on vBulletin, including some operated by Zynga, Electronic Arts, Sony Pictures, NASA, Valve Corporation, and other well known companies.

In July, hackers broke into UbuntuForums.org, a community website for the Ubuntu Linux distribution with over 1.8 million registered accounts, and managed to access information about users, including email addresses and password hashes. The site was using vBulletin.

“In summary, the root cause was a combination of a compromised individual account and the configuration settings in vBulletin, the Forums application software,” Canonical, the company that operates the site, said in a blog post following the incident.


View the original article here

Wednesday, 28 August 2013

Facebook got 25,000 government requests about users in the first half of 2013

Facebook received more than 25,000 requests from governments about its users during the first half of 2013, with nearly half of those requests coming from U.S. law enforcement and related agencies, the company said.

U.S. agencies made 11,000 to 12,000 requests for Facebook user information during the first six months of the year, with the rest of the world’s governments making about 14,600 requests, Facebook said in its first global government requests report, released Tuesday.

Other countries with high numbers of requests: India with 3,245, the U.K. with 1,975, Germany with 1,886, and Italy with 1,705.

The “vast majority” of the requests related to criminal cases, Colin Stretch, Facebook’s general counsel, wrote in the report. In many cases, the requests seek basic subscriber information, such as name and length of membership, while in other cases, law enforcement officials seek IP addresses or account content, he wrote.

Facebook doesn’t honor every request. In the U.S., Facebook provided some information in response to 79 percent of the requests, while in the U.K., it provided some information in 68 percent. The percentage was much lower for several countries. For example, Facebook provided information in response to just 27 percent of Argentina’s 152 requests and 39 percent of France’s 1,547 requests.

“We have stringent processes in place to handle all government data requests,” Stretch wrote. “We believe this process protects the data of the people who use our service, and requires governments to meet a very high legal bar with each individual request in order to receive any information about any of our users. We fight many of these requests, pushing back when we find legal deficiencies and narrowing the scope of overly broad or vague requests.”

Google and some other tech companies have released similar reports about government requests. Google began releasing a government data transparency report in 2009; in the second half of 2012, Google received more than 21,000 requests about its users.

Privacy International, a U.K.-based privacy group, applauded Facebook for releasing the numbers, but said recent leaks about data collection at the U.S. National Security Agency show that these kinds of transparency reports have limited use.

“We are left with a disturbingly hollow feeling regarding Facebook’s gesture, and it has little to do with Facebook itself,” the group said in a blog post. “Since [the NSA documents] have been published and analysed, the veil has been lifted on what information governments actually collect about us.”

The Facebook report only details lawful data requests, the group said. “We are now aware of a terrifying reality—that governments don’t necessarily need intermediaries like Facebook, Google, and Microsoft to get our data,” it added. “They can intercept it over undersea cables, through secret court orders, and through intelligence sharing.”

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Monday, 26 August 2013

Mobile users rely on simple security methods, report says

Nearly 80 percent of smartphone and tablet users choose simple pass codes to protect their devices from unauthorized use, according to an analysis released recently by a maker of mobile device management solutions.

While 85 percent of some 200,000 mobile devices analyzed by Fiberlink had their pass code feature turned on as required by company policy, most of those devices (93 percent) were using simple pass codes to protect the devices.

Fiberlink defined a simple pass code or PIN as a password made up of all numbers or all letters. Of the mobile devices using simple pass codes, almost three quarters (73 percent) had one with a length of four to five characters.

Only 7 percent of the devices analyzed by the company had a complex or alphanumeric pass code. Fiberlink defines a complex password as one made up of letters, numbers and special characters.

"IT is saying it doesn't have the desire to enforce complex passwords on a device that's so heavily balanced between personal use and corporate use," Jonathan Dale, product marketing manager for Fiberlink, said in an interview.

The devices themselves may be contributing to the use of simple pass codes. "It's a usability thing more than anything," said Jamie Cowper, a senior director for Nok Nok Labs.

"The temptation is to go as simple as you can, because long, complex passwords are next to impossible on a small screen in a timely correct fashion," Cowper told CSOonline.

"The balance between security and ease of use has shifted a bit in the mobile space," he said. "You can't ask the same things of a mobile user that you might have done at a desktop machine."

Bill Carey, vice president of Siber Systems, a maker of a password management software, said that ease of typing definitely influenced password choice. "If you're at your computer, you're more inclined to use a more difficult password—something with capital letters and numbers," Carey said in an interview. "But on mobile devices, people don't like typing on those so they're more likely to keep their passwords short."

On the other hand, smartphones have standard features that can be used to authenticate a user that desktop and laptop systems may not have. "Location-based services can be used and biometric information—voice and face—as well," Nok Nok's Cowper said.

"Fingerprint sensors will be on these devices in the near future, possibly next month with Apple's iPhone announcement," he said.

Fiberlink also discovered that the industry which had the highest percentage of devices required to have their pass code feature activated was health care (97 percent), followed by professional services (87 percent), public sector (85 percent), consumer-retail (81 percent), financial services (79 percent), manufacturing (78 percent) and education (41 percent).

However, health care is in the middle of the pack when it comes to the number of devices that have alphanumeric or complex pass codes on them (4 percent). The public sector had the highest number of mobile devices with alphanumeric or complex passwords (18 percent) and education the lowest (1 percent).

Fiberlink's Dale said he was surprised that financial services ranked near the bottom of the table of industries that required its mobile devices to use pass codes. A trend in the industry may have affected that number, he hypothesized.

"Organizations are starting to enforce pass codes only for corporate data and not device data," Dale said. "Companies are putting more restrictive pass codes and permissions around the corporate data on a device and not caring about the pass codes on the device level."

"Let's face it, IT doesn't care about you getting into your phone to text and tweet," he said. "Since our analysis only looked at pass codes used to access a device, that trend wouldn't show up in our data."

With all the flack passwords have received as an authentication method, some commentators have predicted their demise.

Silber's Carey isn't one of those doomsayers. "I'm not sure that anytime soon there's going to be a complete alternative to passwords," he said. "There might some complements to passwords but not necessarily alternatives."

"There have been alternatives for awhile," Carey said. "But none of them seems to have caught on. I think there is a need for passwords and there will always be a need for passwords."

Follow TechHive on Tumblr today.

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Windows 8 users prefer third-party antivirus to bundled tool

Microsoft's Security Essentials (MSE) remains a hugely popular consumer antivirus product but new figures suggest that its Windows 8 successor, Defender, is losing out to third-party alternatives.

Security tools firm OPSWAT has carried out market share analysis of antivirus clients using numbers from its AppRemover tool in the past, but the latest stats are derived from its new security assessment application, Security Score, released in June.

This time the firm divided its results into three categories; the most popular vendors overall, the most encountered individual products and the most encountered individual products that had real-time protection enabled (or not), coming up with some interesting numbers.

Not surprisingly, the frequency of Microsoft's Security Essentials (the standard Windows antivirus client) and Windows Defender (which was upgraded to succeed it on Windows 8) topped the list at a combined 25.8 percent, just ahead of Avast Software's 23.6 percent. A clutch of other familair vendors scored under 10 percent, including AVG, Symantec, Eset, Avira, and Kaspersky.

The top individual product was in fact Avast's Free Antivirus with 19.5 percent, followed by MSE on 18.3 percent, with the Windows 8-only Windows Defender on 7.7 percent.

There were some limitations to this element of the study, starting with the small installed base of Security Score due its recent release. However, the numbers it generated chime with past OPSWAT products share results that used larger data sets.

More interestingly, when the company logged the number of occurrences of each vendor where real-time protection was not enabled (i.e. where the software was present but inactive or disabled), they found that two thirds of Windows 8 users were using a second program for real-time protection.

Windows Defender comes enabled on every install so users who choose to supplement it are making a positive choice to do so. By contrast, MSE on Windows 7, Vista, and XP was far more likely to be enabled, 98 percent of the time to be precise.

"RTP status can be seen as a metric for product usability and/or effectiveness; if a user views an antivirus product as effective and easy to operate, the user is more likely to have that product actively running on his or her machine," concludes OPSWAT's researchers.

It could also be the case that Windows 8 users are confused about the level of protection offered by Defender or even whether, given its self-effacing design, it is present at all. A study by OPSWAT from 2012 found that antivirus programs were often poorly configured.

On cloud backup use, OPSWAT found Google's Drive on 22.5 of systems, Dropbox on 19.5 percent, and Microsoft's SkyDrive (soon to have its name changed) on 15.4 percent. The top ten vendors accounted for more than 83 percent of the market, which suggests that this particular market is now too mature for outsiders to make headway.


View the original article here

Thursday, 22 August 2013

Tumblr issue causes incorrect posts to appear on users' blogs

Sorry, I could not read the content fromt this page.

View the original article here

Bitcoin wallet service to issue refunds after users' funds stolen

A widely used Bitcoin wallet service plans to issue refunds to people who saw their bitcoins stolen as a result of a weakness in its application.

Blockchain.info, which has a Web-based service called My Wallet, has also upgraded its application after finding a vulnerability similar to one discovered earlier this month in some Bitcoin wallet programs running on the Android mobile OS.

“Likely if you have been affected by this problem your coins will have been taken already,” a Blockchain.info official wrote on the Bitcointalk.org forum. “All affected users will be refunded in full.”

The number of affected users is small, said Roger Ver, who is an investor in Blockchain.info, via email. Blockchain.info expects to refund around 50 BTC or $5000, he said.

Interest in Bitcoin has surged since its debut just four years ago. The system offers a low-cost way to transmit virtual currency over the Internet, and many companies and entrepreneurs are working to solve concerns around how to safeguard bitcoins from hackers.

Blockchain.info’s My Wallet uses a browser extension that encrypts a person’s Bitcoin wallet on their computer before it is sent and stored on its servers.

On Tuesday, Blockchain.info upgraded its browser extensions for Chrome and Firefox and its Mac OSX client after it was found a random number generator wasn’t working securely in some cases, potentially exposing people’s bitcoin stashes to theft.

Random numbers are used to sign transactions performed over Bitcoin’s peer-to-peer network as part of its public key cryptography system. If duplicate random number values are used to sign more than one transaction, it may be possible for an attacker to figure out a person’s private signing key and sweep their bitcoins away.

The issue came to light after one user reported on Bitcointalk.org that 1.8 bitcoins—worth around $218 as of Wednesday morning according to Mt. Gox’s market price—were stolen.

The user speculated that Blockchain.info or Firefox had a weakness in code that generates random numbers, similar to the problem found in Android Bitcoin clients earlier this month.

Several Bitcoin clients that used a random number generator component within Android were patched after it was found it occasionally repeated random numbers. Google also issued a patch.

A Blockchain.info official wrote on the forum that My Wallet users on Firefox could be particularly vulnerable. Users should upgrade their My Wallet browser extension to the latest versions, which for Chrome is v2.85, for Firefox is version 1.97 and for Mac clients is version 0.11.

The official also advised that people who only use Blockchain.info’s web interface “should clear their browsers cache before next login.”

Bitcoin addresses—which are used by people to send and receive bitcoins—that may be affected have been listed on Bitcointalk.org.


View the original article here

Twitter's new Vine video service hits 40M users since January

Sorry, I could not read the content fromt this page.

View the original article here

Tuesday, 20 August 2013

New variation of old malware steals log-in credentials from Steam users

A new variant of the Ramnit financial malware is using local Web browser injections in order to steal log-in credentials for Steam accounts, according to researchers from security firm Trusteer.

Ramnit is a computer worm first discovered in 2010 that spreads by infecting executable, HTML and Microsoft Office files on the local computer.

The malware can steal browser cookies and FTP (File Transfer Protocol) credentials stored locally, but it also hooks the browser process in order to modify Web forms and inject rogue code into Web pages, a technique known as a man-in-the-browser (MitB) attack.

The MitB functionality is commonly used by financial malware to trick online banking users into exposing their personal and financial information as well as their online banking credentials.

Security researchers from Trusteer, a company that's in the process of being acquired by IBM, recently identified a new Ramnit variant that targets users of Steam, one of the largest digital distribution and online multiplayer platforms for computer games.

The Ramnit attack circumvents the client-side encryption used for the log-in form fields and can defeat attack detection systems that might run on the server, according to Etay Maor, fraud prevention manager at Trusteer.

Cybercriminals have targeted Steam accounts by using key-logging malware and phishing attacks before. However, Ramnit uses more advanced techniques like Web injection to steal log-in credentials when users sign into the Steam Community site from an infected computer.

According to Maor, when a user accesses the Steam Community log-in page and enters his or her username and password, the form is encrypted using the site's public key. To overcome this, Ramnit modifies the form in a way that allows it to capture the password in plain text.

The user isn't able to tell that anything is wrong, because nothing changes on the log-in page.

Unlike HTML injections that alter the screen the user is familiar with, this injection keeps the screen as is, Maor said Monday via email. However, in the background, the encrypted "password" field is replaced with a non-encrypted field.

When the user fills in the form and submits it, the malware intercepts the request, reads the data from the non-encrypted field and deletes the field before sending the request to the Steam Web server. According to Maor, this can hide the attack from security software that scans for unusual form elements in order to detect malware injections.

For example, if a submitted log-in form altered by banking malware contains a credit card number field that shouldn't be there in the first place, it could indicate to the server operator that the user was a victim of a MitB attack. However, in this Steam attack, Ramnit makes sure the server never gets to see the injected field.

The malware could use key logging instead of HTML injections to steal the data, but it would take the malware operator a lot of time to separate the actual credentials from everything else in the key logging file, Maor said. "The file itself is not easy to work with as opposed to forms that give you the data elements in a structured format. It's simply a matter of saving time and effort."

In the past, Ramnit has mainly targeted banks, but Trusteer researchers have already seen it being used to target customers of non-banking institutions, organizations and services, Maor said. "It all depends on what the operator wants to achieve; it is a sophisticated tool that can be used for multiple targets regardless of their orientation."


View the original article here

Friday, 16 August 2013

How non-Dropbox users can send files to your Dropbox account

Smart fixes for your PC hassles

Dbinbox.

As any Dropbox user knows, it's pretty easy to share a cloud-stored file with someone; just click the share icon to get a link you can distribute as needed.

Ah, but what about the other way around? What if someone wants to send a file to you via Dropbox? Unless they have Dropbox accounts of their own, they can't.

Now they can. Browser-based Dbinbox enables Dropbox sharing in the other direction: It generates a custom link that others can use to send files to your Dropbox.

All you do is type in a desired user name, then click Link with your Dropbox. You'll have to give Dbinbox permission, of course, after which you'll find a newly added Dbinbox folder inside your Apps folder.

Now, just hand out your custom Dbinbox link. When someone uses it, he or she can drag and drop files right to the browser window or use a file selector. There's even an option to send a message (which gets delivered as a text file), a nice touch.

For a little added security, Dbinbox lets you create an access code you can require users to enter before sending files your way.

This is a great little service that overcomes one of Dropbox's hassles—few and far between as they are. There's no charge to use it, though the developer does accept Bitcoin donations.

Contributing Editor Rick Broida writes about business and consumer technology. Ask for help with your PC hassles at hasslefree@pcworld.com. Sign up to have the Hassle-Free PC newsletter e-mailed to you each week.

For more than 20 years, Rick Broida has written about all manner of technology, from Amigas to business servers to PalmPilots. His credits include dozens of books, blogs, and magazines. He sleeps with an iPad under his pillow.
More by Rick Broida

Get the NEW TechHive Digital Photography Superguide and get the most from your digital cameras!

View the original article here